PT-2026-38588 · Github · Github Enterprise Server

Published

2026-05-07

·

Updated

2026-05-10

·

CVE-2026-6736

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitHub Enterprise Server versions prior to 3.21
Description An authentication bypass allows an unauthenticated attacker to create a local user account, bypassing the configured external identity provider. When external authentication is enabled, the 'signup' endpoint fails to properly enforce authentication restrictions, enabling account creation and session establishment without identity provider validation. The resulting account is limited to the default base permissions of the instance. Exploitation requires network access to an instance configured with an external authentication provider.
Recommendations Update to version 3.20.2, 3.19.6, 3.18.9, 3.17.15, or 3.16.18.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-6736

Affected Products

Github Enterprise Server